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Art Unit: 2131 

This action is in response to the communication filed on December 18, 2000. 

DETAILED ACTION 

1 . Claims 1-57 have been examined. 

Title 

2. The title of the invention is acceptable. 

Priority 

3. No claim for priority has been made for this application. 

4. The effective filing date for the subject matter defined in the pending claims in 
this application is 12/20/2000. 



Information Disclosure Statement 

The information disclosure statement (IDS) submitted on May 30, 2001 is in 
compliance with the provisions of 37 CFR 1 .97. Accordingly, the examiner is 
considering the Infomnation disclosure statement. 

Drawings 

5. The drawings filed on July 12, 2001 are acceptable for examination proceedings. 

Specification 

6. The abstract of the disclosure Is objected to for the following reasons: 
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The phrase "is provided" of line 1 can be implied and therefore must be 
removed. 

The title of the invention listed at the top of the abstract is not in 
accordance with Title 37 C.F.R. 1.72 and therefore must be removed. 
Correction is required. See MPEP § 608.01(b). 

7. The disclosure is objected to because of the following informalities: 
Page 6 Line 17 recites "O Of course," which is grammatically incorrect. 
Appropriate correction is required. 

8. The applicant is advised to check for other spelling and grammatical errors 
throughout the specification. Applicant's cooperation is requested in correcting any 
errors of which applicant may become aware in the specification. 

Claim Rejections - 35 USC § 102 

9. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that 
form the basis for the rejections under this section made in this Office action: 

A person shall be entitled to a patent unless - 

(b) the invention was patented or described in a printed publication in this or a 
foreign country or in public use or on sale in this country, more than one year 
prior to the date of application for patent in the United States. 

10. Claims 1-14, 20-33, 39-52 rejected under 35 U.S.C. 102(b) as being anticipated 
by He (U.S. Patent 5,944,824) hereinafter referred to as He. 

11. Claim 1 recites changing the SSO password in response to receiving a change 
instruction. He disclosed a programmed method and system for changing passwords in 
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a Single Sign-On (SSO) environment (See He Col. 13 Paragraphs 3-7). He disclosed 
that in response to a request to modify a user account (See He Col. 13 Lines 12-13) a 
new password is generated (See He Col. 13 Lines 20-22) and the old password is set to 
the new password (See He Col. 13 Lines 43-45). 

Claim 1 further recites retrieving and modifying a target password. He disclosed 
retrieving the target password (See He Col. 13 Lines 22-25). He Further disclosed 
changing a target NE password to the specified new password (See He Col. 13 Lines 
31-35). 

12. Regarding claims 2-4, He disclosed providing the modified password target 
password to the network element, or client (See He Col. 10 Paragraphs 2-3). It is 
inherent that the password was first stored in order for it to have been provided in the 
ticket, as is specified by He (See He Col. 10 Lines 16-21). 

13. Regarding claims 5, 8-9, He disclosed password generation by a random number 
generator or by manually entering the password (See He Col. 13 Paragraph 4). 
Because this task was carried out by the network security administrator (See He Col. 13 
Paragraph 3), it was inherent that a menu was provided such that the password 
generation method could be chosen. 

14. Regarding claims 6-7, He disclosed users using one password for multiple 
applications (See He Col. 1 Paragraph 5). 

15. Regarding claim 10, He disclosed random password generation being performed 
in a server (See He Col. 1 1 Lines 40-41 ). 
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16. Regarding claim 1 1 , He disclosed the use of password policy in generating tlie 
random passwords (See He Col. 12 Paragraph 2). It is inherent that the password 
policy was determined in order for it to have been used. 

1 7. Regarding claim 12-14, He disclosed different types of passwords. He disclosed 
standard user passwords (See He Col. 1 1 Paragraph 2), network element passwords 
(See He Col. 8 Paragraph 8), and Super-User passwords (See He Col. 8 Paragraph 8). 
It was inherent that each of these groups had some sort of password policy to be 
checked against (See He Col. 12 Paragraph 2). 

18. Regarding claims 20-33, He disclosed a programmed method and system for 
changing passwords in a Single Sign-On (SSO) environment (See He Claims 1 and 5). 
Because He claimed a programmed method to be run in a network, it was inherent that 
the method comprised a computer program product in computer readable media. 
Claims 20-33 are therefore rejected for the same reasons as applied to claims 1-14 
above. 

19. Regarding claims 39-52, He disclosed a programmed method and system for 
changing passwords in a Single Sign-On (SSO) environment (See He Claims 1 and 5). 
Claims 39-52 are therefore rejected for the same reasons as applied to claims 1-14 
above. 
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Claim Rejections - 35 USC § 103 



20. The following is a quotation of 35 U.S.C. 103(a) which forms the basis for all 

obviousness rejections set forth in this Office action: 

(a) A patent may not be obtained though the invention is not identically disclosed 
or described as set forth in section 102 of this title, if the differences between the 
subject matter sought to be patented and the prior art are such that the subject 
matter as a whole would have been obvious at the time the invention was made 
to a person having ordinary skill in the art to which said subject matter pertains. 
Patentability shall not be negatived by the manner in which the invention was 
made. 

21. Claims 15, 34, and 53 rejected under 35 U.S.C. 103(a) as being unpatentable 
over He as applied to claims 5, 24, and 43 respectively above, and further in vi,ew of 
Redpath (U.S. Patent 5,854,629) hereinafter referred to as Redpath. 

He disclosed password generation by a random number generator or by 
manually entering the password (See He Col. 13 Paragraph 4). However, He failed to 
disclose the use of a Graphical User Interface (GUI) for implementing this selection. 

Redpath teaches the GUIs were created in order to simplify interaction with 
computer programs for end users of computer programs, such that end users do not 
need to know specific commands in order to effectively use the computer program (See 
Redpath Col. 1 Paragraph 2). 

It would have been obvious to the ordinary person skilled in the art at the time of 
invention to employ the teachings of Redpath in the invention of He such that the user is 
supplied a GUI menu in order to select a password generation method. This would 
have been obvious because the ordinary person skilled in the art would have been 
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motivated to provide a simple interface for the user to interact with the password- 
changing program. 

22. Claims 16, 35, and 54 rejected under 35 U.S.C. 103(a) as being unpatentable 
over He as applied to claims 1 , 20, and 39 respectively above, and further in view of 
Prafullchandra (U.S. Patent 5,734,718) hereinafter referred to as Prafullchandra. 

He disclosed retrieving and changing target passwords (See He Col. 13 
Paragraphs 3-7), but He failed to disclose a change target password policy. However, 
He did disclose that having different administrative policies in individual network 
elements can be problematic (See He Col. 1 Paragraph 5). 

Prafullchandra teaches that requiring users to change passwords at 
predetermined intervals can enhance system security (See Prafullchandra Col. 2 
Paragraph 3). 

It would have been obvious to the ordinary person skilled in the art at the time of 
the invention to employ the password aging and changing policy of Prafullchandra to the 
password changing system and method of He. This would have been obvious because 
the ordinary person skilled in the art would have been motivated to enhance the security 
in the network of He. 

23, Claims 17-19, 36-38, 55-57 are rejected under 35 U.S.C. 103(a) as being 
unpatentable over the combination of He and Prafullchandra as applied to 16, 35, and 
54 respectively above. 

He disclosed different types of passwords. He disclosed standard user 

passwords (See He Col, 1 1 Paragraph 2), network element passwords (See He Col. 8 
Paragraph 8), and Super-User passwords (See He Col. 8 Paragraph 8). 
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It would have been obvious to the ordinary person skilled in the art at the time of 
invention to employ the aging policy of Prafullchandra to all the types of passwords of 
He. This would have been obvious because the ordinary person skilled in the art would 
have been motivated to enhance the security of all the passwords, regardless of their 
type. 
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Conclusion 



24. The prior art made of record and not relied upon is considered pertinent to 
applicant's disclosure. 

a. Limsico (U.S. Patent 5,793,952) disclosed a secure remote password 
graphic interface with the ability to change passwords. 

b. Anderson et al. (U.S. Patent 6,144,959) disclosed a method for managing 
user accounts in a distributed network. 

c. OIkin (U.S. Patent 5,768,503) disclosed a middleware authentication and 
security mechanim. 

d. Dare et al. (U.S. Patent 5,684,950) disclosed a method of authentication 
via SSO. 

e. Cohen etal. (U.S. Patent 6,178,511) disclosed an SSO mechanism for 
coordinating user target logons. 

f. Birnbaum (U.S. Patent 5,797,128) disclosed a hierarchical policy for 
computer system administration. 

g. Fang et al. (U.S. Patent 6,243,816) disclosed a SSO key manager. 



25. Any inquiry concerning this communication should be directed to Matthew 
Henning whose telephone number is (703) 305-0713. The examiner can normally be 
reached Monday-Friday from 9am to 4pm, EST. 



Application/Control Number: 09/740,400 



Page 10 



Art Unit: 2131 

If attempts to reach examiner by telephone are unsuccessful, the examiner's 
acting supervisor, Ayaz Sheikh, can be reached at (703) 305-9648. The fax phone 
number for this group is (703) 305-371 8. 

Any Inquiry of general nature or relating to the status of this application or 
proceeding should be directed to the Group receptionist whose telephone number Is 
(703) 305-3900. 





Assistant Examiner 
Art Unit 2131 



